exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 903 discussion

Actual exam question from Isaca's CISM
Question #: 903
Topic #: 1
[All CISM Questions]

Which of the following BEST enables an information security manager to demonstrate the effectiveness of the information security and risk program to senior management?

  • A. Updated risk assessments
  • B. Audit reports
  • C. Counts of information security incidents
  • D. Monthly metrics
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
koala_lay
8 months, 2 weeks ago
Selected Answer: B
Option B, Audit reports, would be the best way to demonstrate the effectiveness of the information security and risk program to senior management. Audit reports provide an independent and objective evaluation of the program's controls, processes, and compliance with established policies and standards. These reports highlight any weaknesses or areas of improvement, allowing senior management to make informed decisions and take necessary actions to mitigate risk. Additionally, audit reports often include recommendations and action plans, which can further enhance the effectiveness of the program.
upvoted 3 times
...
richck102
9 months, 1 week ago
Selected Answer: D
D. Monthly metrics
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...